
EC-CouncilCertified Penetration Testing Professional
Domain 6Objective 2
IoT Penetration Testing CPENT Practice Questions (Page 4)
Part of the Advanced Exploitation and IoT domain, which makes up ~17% of our current practice bank.
49questions here
10free pages
8concepts
Questions 16–20
- 16
You are testing a smart door lock that is controlled by a mobile app via BLE. The app also has a cloud backend for remote access. You have discovered that the BLE pairing process uses a static PIN that is printed on the device. An attacker with physical access to the device can read the PIN and pair with the lock. What is the MOST effective mitigation to recommend?
Select an answer first - 17
You are testing a smart lighting system that uses Zigbee for device-to-device communication and a Zigbee coordinator that connects to the internet via a hub. You want to test for unauthorized control of the lights. Which of the following is the MOST effective testing approach?
Select an answer first - 18
During a firmware analysis of an IP camera, a tester extracts the root filesystem and finds a script that connects to a remote server using hardcoded credentials. The tester wants to determine if these credentials are also used elsewhere in the device. Which step should the tester take next?
Select an answer first - 19
Which vulnerability is commonly tested in the cloud web interface of an IoT system?
Select an answer first - 20
Which hardware interface is commonly used for debugging and provides a serial console to the device?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.